--- # Настройка Keycloak - name: Keycloak prepare clients block: - name: Create or update Keycloak client - grafana_oidc community.general.keycloak_client: auth_keycloak_url: "https://{{ iam_fqdn }}" auth_realm: master auth_username: "{{ iam_admin_username }}" auth_password: "{{ iam_admin_pass }}" state: present validate_certs: false realm: "{{ iam_realm }}" client_id: grafana_oidc name: client_grafana_oidc enabled: true root_url: "https://{{ mon_fqdn }}" admin_url: "https://{{ mon_fqdn }}" redirect_uris: - "https://{{ mon_fqdn }}/login/generic_oauth" web_origins: - "https://{{ mon_fqdn }}" client_authenticator_type: client-secret secret: "{{ grafana_client_secret }}" standard_flow_enabled: true direct_access_grants_enabled: true protocol: openid-connect public_client: false # delegate_to: localhost - name: Create or update Keycloak client - gem-event-client community.general.keycloak_client: auth_keycloak_url: "https://{{ iam_fqdn }}" auth_realm: master auth_username: "{{ iam_admin_username }}" auth_password: "{{ iam_admin_pass }}" state: present validate_certs: false realm: "{{ iam_realm }}" client_id: "{{ user_app_client_id }}" enabled: true name: client_user_app bearer_only: false redirect_uris: - /* web_origins: - /* client_authenticator_type: client-secret secret: "{{ user_app_client_secret }}" standard_flow_enabled: true direct_access_grants_enabled: false service_accounts_enabled: true protocol: openid-connect public_client: false # delegate_to: localhost when: user_event_publisher.enable == "yes" - name: Create or update Keycloak client - gem-auth-client (cowork) community.general.keycloak_client: auth_keycloak_url: "https://{{ iam_fqdn }}" auth_realm: master auth_username: "{{ iam_admin_username }}" auth_password: "{{ iam_admin_pass }}" state: present validate_certs: false realm: "{{ iam_realm }}" client_id: gem-auth-client enabled: true name: client_gem-auth-client bearer_only: false redirect_uris: - /* - https://web.co-work.ru/* - cowork://oauth2redirect - app://links.cowork.ru/oauth2redirect - "{{ admin_app_url }}/*" web_origins: - + client_authenticator_type: client-secret secret: "{{ gem_auth_client_secret }}" standard_flow_enabled: true direct_access_grants_enabled: true protocol: openid-connect public_client: false # delegate_to: localhost when: instance_app == "cowork" - name: Create or update Keycloak client - gem-auth-client (gemteam) community.general.keycloak_client: auth_keycloak_url: "https://{{ iam_fqdn }}" auth_realm: master auth_username: "{{ iam_admin_username }}" auth_password: "{{ iam_admin_pass }}" state: present validate_certs: false realm: "{{ iam_realm }}" client_id: gem-auth-client enabled: true name: client_gem-auth-client bearer_only: false redirect_uris: - /* - https://demo-web.gem.team/* - gemteam://oauth2redirect - app://links.gem.team/oauth2redirect - https://web.gem.team/* - "{{ admin_app_url }}/*" web_origins: - + client_authenticator_type: client-secret secret: "{{ gem_auth_client_secret }}" standard_flow_enabled: true direct_access_grants_enabled: true protocol: openid-connect public_client: false # delegate_to: localhost when: instance_app == "gemteam" - name: Set default and optional client scopes on gem-auth-client community.general.keycloak_clientscope_type: auth_keycloak_url: "https://{{ iam_fqdn }}" auth_realm: master auth_username: "{{ iam_admin_username }}" auth_password: "{{ iam_admin_pass }}" realm: "{{ iam_realm }}" validate_certs: false client_id: "gem-auth-client" default_clientscopes: ['acr', 'basic', 'email', 'profile', 'roles', 'user_id', 'web-origins'] optional_clientscopes: ['address', 'microprofile-jwt', 'offline_access', 'organization', 'phone'] # register: iam_scope # - name: Debug iam_scope # debug: # msg: "{{ iam_scope }}"